VendorsJuniperjunosall versions
Vulnerabilities

Juniper Junos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

791CVEs
CVE-2023-44201
Junos OS and Junos OS Evolved: A local attacker can retrieve sensitive information and elevate privileges on the device to an authorized user.
Published 2023-10-12 · Modified
5.5EPSS 0.001
CVE-2014-3822
Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4.
Published 2014-07-11 · Modified
5.4EPSS 0.017
CVE-2013-7313
The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.
Published 2014-01-23 · Modified
5.4EPSS 0.011
CVE-2025-60010
Junos OS and Junos OS Evolved: Device allows login for user with expired password
Published 2025-10-09 · Analyzed
5.4EPSS 0.002
CVE-2023-36846
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.935
CVE-2023-36844
Junos OS: EX Series: A PHP vulnerability in J-Web allows an unauthenticated attacker to control important environment variables
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.900
CVE-2023-36847
Junos OS: EX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload arbitrary files
Published 2023-08-17 · Analyzed
5.3KEVEPSS 0.835
CVE-2018-0061
Junos OS: Denial of service in telnetd
Published 2018-10-10 · Modified
5.3EPSS 0.023
CVE-2017-2340
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and destined to M/MX series routers can result in a PFE (Packet Forwarding Engine) hang or crash.
Published 2017-04-24 · Modified
5.3EPSS 0.022
CVE-2017-10621
Junos OS: Denial of service vulnerability in telnetd
Published 2017-10-13 · Modified
5.3EPSS 0.018
CVE-2016-1256
Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R7, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D18 or 14.1X53-D30, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R4, 15.1 before 15.1R2, and 15.1X49 before 15.1X49-D10 allow remote attackers to cause a denial of service via a malformed IGMPv3 packet, aka a "multicast denial of service."
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2016-1258
Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R8, 14.1 before 14.1R6, and 14.2 before 14.2R5, allows remote attackers to cause a denial of service (J-Web crash) via unspecified vectors.
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2016-1260
Juniper Junos OS before 13.2X51-D36, 14.1X53 before 14.1X53-D25, and 15.2 before 15.2R1 on EX4300 series switches allow remote attackers to cause a denial of service (network loop and bandwidth consumption) via unspecified vectors related to Spanning Tree Protocol (STP) traffic.
Published 2016-01-15 · Modified
5.3EPSS 0.017
CVE-2020-1680
Junos OS: MX Series: MS-MPC/MIC might crash when processing malformed IPv6 packet in NAT64 configuration.
Published 2020-10-16 · Modified
5.3EPSS 0.013
CVE-2020-1628
Junos OS: EX4300: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces
Published 2020-04-08 · Modified
5.3EPSS 0.013
CVE-2020-1665
Junos OS: MX series/EX9200 Series: IPv6 DDoS protection does not work as expected.
Published 2020-10-16 · Modified
5.3EPSS 0.013
CVE-2021-0229
Junos OS: Receipt of specific packets could lead to Denial of Service in MQTT Server
Published 2021-04-22 · Modified
5.3EPSS 0.012
CVE-2019-0005
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform packet matching on any IPv6 extension headers. This issue may allow IPv6 packets that should have been blocked to be forwarded. IPv4 packet filtering is unaffected by this vulnerability. Affected releases are Juniper Networks Junos OS on EX and QFX series;: 14.1X53 versions prior to 14.1X53-D47; 15.1 versions prior to 15.1R7; 15.1X53 versions prior to 15.1X53-D234 on QFX5200/QFX5110 series; 15.1X53 versions prior to 15.1X53-D591 on EX2300/EX3400 series; 16.1 versions prior to 16.1R7; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R3; 17.3 versions prior to 17.3R3; 17.4 versions prior to 17.4R2; 18.1 versions prior to 18.1R2.
Published 2019-01-15 · Modified
5.3EPSS 0.012
CVE-2023-36851
Junos OS: SRX Series: A vulnerability in J-Web allows an unauthenticated attacker to upload and download arbitrary files
Published 2023-09-26 · Analyzed
5.3KEVEPSS 0.011
CVE-2021-31361
Junos OS: QFX Series and PTX Series: FPC resource usage increases when certain packets are processed which are being VXLAN encapsulated
Published 2021-10-19 · Modified
5.3EPSS 0.010
CVE-2020-1655
Junos OS: MX Series: PFE crash on MPC7/8/9 upon receipt of large packets requiring fragmentation
Published 2020-07-17 · Modified
5.3EPSS 0.010
CVE-2021-0273
Junos OS and Junos OS Evolved: Trio Chipset: Denial of Service due to packet destined to device's interfaces.
Published 2021-04-22 · Modified
5.3EPSS 0.010
CVE-2020-1661
Junos OS: jdhcpd process crash when forwarding a malformed DHCP packet.
Published 2020-10-16 · Modified
5.3EPSS 0.010
CVE-2021-31369
Junos OS: MX Series: Traffic drops will be observed if MS-MPC/MS-PIC resources are consumed by certain traffic causing a partial DoS
Published 2021-10-19 · Modified
5.3EPSS 0.010
CVE-2021-0294
Junos OS: QFX5000 Series and EX4600 Series: Enhanced storm control might not work leading to partial Denial of Service
Published 2021-07-15 · Modified
5.3EPSS 0.009
CVE-2017-10604
Junos OS: SRX Series: Cluster configuration sync failures occur if the root user account is locked out
Published 2017-07-14 · Modified
5.3EPSS 0.009
CVE-2021-31371
Junos OS: QFX5000 Series: Traffic from the network internal to the device (128.0.0.0) may be forwarded to egress interfaces.
Published 2021-10-19 · Modified
5.3EPSS 0.008
CVE-2022-22204
Junos OS: MX Series and SRX Series: When receiving a specific SIP packets stale call table entries are created which eventually leads to a DoS for all SIP traffic
Published 2022-07-20 · Modified
5.3EPSS 0.007
CVE-2023-28968
Junos OS: SRX Series: Policies that rely on JDPI-Decoder actions may fail open
Published 2023-04-17 · Modified
5.3EPSS 0.006
CVE-2024-21596
Junos OS and Junos OS Evolved: A specific BGP UPDATE message will cause a crash in the backup Routing Engine in NSR-enabled devices
Published 2024-01-12 · Modified
5.3EPSS 0.005
CVE-2022-22244
Junos OS: Unauthenticated XPath Injection vulnerability in J-Web
Published 2022-10-18 · Modified
5.3EPSS 0.005
CVE-2023-28963
Junos OS: User-controlled input vulnerability in J-Web
Published 2023-04-17 · Modified
5.3EPSS 0.005
CVE-2024-21610
Junos OS: If in a scaled CoS scenario information on CoS state is gathered mgd processes get stuck
Published 2024-04-12 · Modified
5.3EPSS 0.005
CVE-2026-33799
Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash
Published 2026-07-09 · Analyzed
5.3EPSS 0.004
CVE-2023-44188
Junos OS: jkdsd crash due to multiple telemetry requests
Published 2023-10-11 · Modified
5.3EPSS 0.003
CVE-2024-21607
Junos OS: MX Series and EX9200 Series: If the "tcp-reset" option used in an IPv6 filter, matched packets are accepted instead of rejected
Published 2024-01-12 · Modified
5.3EPSS 0.003
CVE-2026-57031
Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect
Published 2026-07-09 · Analyzed
5.3EPSS 0.002
CVE-2023-28984
Junos OS: QFX Series: The PFE may crash when a lot of MAC addresses are being learned and aged
Published 2023-04-17 · Modified
5.3EPSS 0.002
CVE-2013-4689
J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.
Published 2013-10-17 · Modified
5.1EPSS 0.010
CVE-2024-21615
Junos OS and Junos OS Evolved: A low-privileged user can access confidential information
Published 2024-04-12 · Analyzed
5.1EPSS 0.002
← Prev19 / 20Next →